Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2518

Опубликовано: 26 апр. 2016
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.

An out-of-bounds access flaw was found in the way ntpd processed certain packets. An authenticated attacker could use a crafted packet to create a peer association with hmode of 7 and larger, which could potentially (although highly unlikely) cause ntpd to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ntpNot affected
Red Hat Enterprise Linux 6ntpFixedRHSA-2016:114131.05.2016
Red Hat Enterprise Linux 6.7 Extended Update SupportntpFixedRHSA-2016:155203.08.2016
Red Hat Enterprise Linux 7ntpFixedRHSA-2016:114131.05.2016

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1331468ntp: out-of-bounds references on crafted packet

EPSS

Процентиль: 73%
0.00785
Низкий

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 8 лет назад

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.

CVSS3: 5.3
nvd
больше 8 лет назад

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.

CVSS3: 5.3
debian
больше 8 лет назад

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x befor ...

CVSS3: 5.3
github
больше 3 лет назад

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.

oracle-oval
около 9 лет назад

ELSA-2016-1141: ntp security update (MODERATE)

EPSS

Процентиль: 73%
0.00785
Низкий

2.1 Low

CVSS2